Security Risk Assessment & Analysis Flashcards
7 cards from real CSS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Security Risk Assessment & Analysis flashcards as text
Which risk response strategy involves purchasing cyber insurance to offset potential financial losses from a breach?
Answer: Risk transference
Risk transference shifts the financial consequence of a risk to a third party, most commonly through insurance policies or contractual agreements.
An organization uses the DREAD model to rate security risks. Which component of DREAD measures how easily an attack can be replicated by others?
Answer: Reproducibility
Reproducibility in the DREAD model scores how easily and consistently an attack can be repeated once the method is known.
During a risk assessment workshop, participants disagree on risk ratings. Which technique uses rounds of anonymous voting and feedback to build consensus?
Answer: Delphi technique
The Delphi technique gathers expert opinions through multiple rounds of anonymous questionnaires with feedback, converging toward consensus without groupthink.
A risk assessment reveals a high-severity vulnerability in a legacy system that cannot be patched. The organization deploys additional monitoring and firewall rules instead. This is an example of:
Answer: Compensating controls
Compensating controls are alternative safeguards applied when the primary control (patching) is not feasible, providing equivalent risk reduction.
What does the Common Vulnerability Scoring System (CVSS) Base Score measure?
Answer: The intrinsic characteristics of a vulnerability independent of time or environment
The CVSS Base Score reflects the intrinsic qualities of a vulnerability—such as attack vector, complexity, and impact—that are constant over time and across environments.
Which asset valuation method determines value based on what it would cost to replace an asset with one of equivalent functionality at today's prices?
Answer: Replacement cost
Replacement cost valuation determines an asset's worth based on the current market cost to acquire or build an equivalent asset.
In threat modeling, what is the purpose of identifying 'entry points'?
Answer: To enumerate the locations where a threat actor can interact with or inject data into a system
Entry points define where attackers can interact with or introduce data into a system, helping focus threat modeling on the highest-exposure interfaces.